PT-2026-95002 · Mport · Mport
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
The audit command in
mport/mport.c incorrectly handles argument parsing. It computes option-adjusted local argv and local argc values but passes the original argument entry to the audit package() function. If an option like -r is used before a package name, the stale optind state and unadjusted argument may lead the system to audit the option token instead of the intended package. This results in false-negatives, potentially leaving vulnerable packages unidentified.Recommendations
Update to version 2.7.8.
Exploit
Fix
RCE
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport